PT-2026-83734 · Hulumi · Hulumi

CVE-2026-82857

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions hulumi versions prior to 1.3.2
Description A privilege escalation issue exists in the weekly integration IAM (Identity and Access Management) policy. This flaw allows role lifecycle operations on af-e2e-* roles due to insufficient boundary restrictions. An attacker with the documented principal can exploit this to create persistent roles with higher privileges within the sandbox account.
Recommendations Update hulumi to version 1.3.2 or later.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82857
GHSA-35QR-VX94-M5X3

Affected Products

Hulumi